component-vuln-intel
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document is an explicit playbook for discovering, locating, and obtaining exploit PoCs and exposed targets (FOFA/Shodan/Zoomeye) and includes guidance to bypass blocks and use proxies—instructions that clearly facilitate unauthorized compromise and exploitation.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 源自 SKILL.md 的联网情报收集流程会通过浏览器导航与 GitHub API 直接读取外部站点/社区搜索结果与 GitHub 仓库 README/代码等公开文本(例如在第2、4、6步等对第三方页面与 GitHub 内容进行抓取与解析),因此存在被外部作者提交的提示注入文本影响运行时的风险。
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata